AWS Certified Security - Specialty (#32)

For compliance reasons, an organization limits the use of resources to three specific AWS regions. It wants to be alerted when any resources are launched in unapproved regions. Which of the following approaches will provide alerts on any resources launched in an unapproved region?

Develop an alerting mechanism based on processing AWS CloudTrail logs.
Monitor Amazon S3 Event Notifications for objects stored in buckets in unapproved regions.
Analyze Amazon CloudWatch Logs for activities in unapproved regions.
Use AWS Trusted Advisor to alert on all resources being created.